Vulnerabilities > CVE-2013-3969 - Resource Management Errors vulnerability in Mongodb
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
The find prototype in scripting/engine_v8.h in MongoDB 2.4.0 through 2.4.4 allows remote authenticated users to cause a denial of service (uninitialized pointer dereference and server crash) or possibly execute arbitrary code via an invalid RefDB object.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 5 |
Common Weakness Enumeration (CWE)
Exploit-Db
description | MongoDB 'conn' Mongo Object Remote Code Execution Vulnerability. CVE-2013-3969. Remote exploits for multiple platform |
id | EDB-ID:38669 |
last seen | 2016-02-04 |
modified | 2013-06-04 |
published | 2013-06-04 |
reporter | SCRT Security |
source | https://www.exploit-db.com/download/38669/ |
title | MongoDB 'conn' Mongo Object Remote Code Execution Vulnerability |
Nessus
NASL family | Databases |
NASL id | MONGODB_2_5_1.NASL |
description | The version of the remote MongoDB server is a version prior to version 2.4.5 / 2.5.1. It is, therefore, potentially affected by the following vulnerabilities : - A remote attacker can gain elevated privileges when authenticating as the internal __system user name for arbitrary databases. (CVE-2013-4650) - The JavaScript engine is vulnerable to a flaw that could be triggered remotely to cause a segmentation fault, or potentially arbitrary code execution. (CVE-2013-3969) |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 67243 |
published | 2013-07-11 |
reporter | This script is Copyright (C) 2013-2018 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/67243 |
title | MongoDB < 2.4.5 / 2.5.1 Multiple Vulnerabilities |
code |
|
References
- http://blog.scrt.ch/2013/06/04/mongodb-rce-by-databasespraying/
- http://blog.scrt.ch/2013/06/04/mongodb-rce-by-databasespraying/
- http://secunia.com/advisories/54170
- http://secunia.com/advisories/54170
- http://www.mongodb.org/about/alerts/
- http://www.mongodb.org/about/alerts/
- http://www.openwall.com/lists/oss-security/2013/07/30/10
- http://www.openwall.com/lists/oss-security/2013/07/30/10
- https://jira.mongodb.org/browse/SERVER-9878
- https://jira.mongodb.org/browse/SERVER-9878